Sanya

Cybersecurity SOC AI Agent Automation

I explore security operations, incident response, cloud security, and AI-driven automation.

顺势而为,趋吉避凶

About

关于

Background

Born in 2002, Sanya is focused on cybersecurity operations and AI-enabled security automation. His work spans SOC operations, EDR analysis, incident response, digital forensics, cloud security, detection engineering, and AI Agent orchestration.

研究方向

我关注安全运营、事件响应、数字取证、云安全与 AI Agent 自动化,希望将传统 SOC 能力逐步演进为智能化安全编排能力。

Focus Areas

研究领域

SOC Operations

Security operations center workflows, alert triage, and operational efficiency.

EDR Analysis

Endpoint detection and response, threat hunting, and behavioral analysis.

Incident Response

Structured response methodologies, containment strategies, and post-incident analysis.

Digital Forensics

Evidence collection, forensic analysis, and chain of custody procedures.

Cloud Security

Cloud-native security architectures, compliance frameworks, and threat detection.

AI Agent

Autonomous security agents, LLM-powered analysis, and intelligent orchestration.

Security Automation

Playbook development, SOAR integration, and workflow optimization.

Detection Engineering

Detection rule development, Sigma/YARA authoring, and threat-informed defense.

Projects

项目

Kali Pentest Agent

AI-powered penetration testing agent built on Kali Linux with automated reconnaissance and exploitation workflows.

AI Agent Pentest Python

SOC Automation Playbooks

Collection of SOAR playbooks for common SOC workflows including alert enrichment, escalation, and response.

SOAR Automation SOC

Sentinel Detection Rules

Custom Microsoft Sentinel analytics rules, workbooks, and hunting queries for enterprise threat detection.

Sentinel Detection KQL

AI Security Orchestrator

Experimental platform for LLM-driven security orchestration, automating investigation and response decisions.

AI Orchestration LLM